OpenSSF Sets Minimum Security Baselines for Open Source Projects
ID: bef48fbf-9704-58e9-9e7a-34795b9ad0bd
STIX ID: report--bef48fbf-9704-58e9-9e7a-34795b9ad0bd
Feed Name: Dark Reading
The OpenSSF announced the Open Source Project Security (OSPS) Baseline: a three-tiered minimum-security framework for open-source projects that defines Level 1 "universal security floor" requirements (e.g., multifactor authentication, contributor controls, release and licensing guidance, version control hygiene) and Level 3 controls for privilege management, code release, and testing. The baseline is intended to help maintainers and adopters quickly understand and adopt fundamental security practices, is recommended at least at Level 1 for all projects (Level 3 for widely used projects), and is not meant to replace existing tools or serve as a comparative scoring mechanism.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
